Advisory summary
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device.
A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device. Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS Security Impact Rating: High CVE: CVE-2026-20362
What the vendor says is affected
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
What the vendor recommends
Cisco plans to release software updates that address this vulnerability.
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Cisco
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.